From the initial analysis to the certificate: the path to ISO 27001 certification follows a clearly structured process. Here you can find out in detail which steps are crucial.
Planning with foresight
The path to ISO 27001 certification begins with a gap analysis that examines existing processes, systems and security measures and identifies security gaps. The scope is then defined in consultation with STACKIT. Whether location, department or entire company: A clearly defined scope is essential. Equally important is a competent project team that coordinates the introduction of the ISMS.
Setting up an ISMS: Identify risks, secure processes
Structured risk management is at the heart of ISO 27001. Vulnerabilities are identified, evaluated and addressed with suitable security measures (controls). These measures are implemented in accordance with the standard specifications. At the same time, central documentation is created - from access rules to binding guidelines on information security. Training courses ensure that the implementation also reaches the employees.
Internal control and management assessment
Before the external audit begins, an initial audit takes place: an internal auditor checks whether the ISMS has been implemented effectively. The company management then assesses in the management review whether the system is working and can be further developed. This check is a prerequisite for the subsequent certification audit.
Certification by an independent body
The certification audit takes place in two stages: In Stage 1, the certification body checks documents and preparations. Stage 2 is followed by an on-site audit to assess processes and the security awareness of employees. If successful, you will receive the ISO 27001 certificate. This is valid for three years and includes annual surveillance audits.
Continuous improvement
Even after certification, regular surveillance audits check the effectiveness of the system. The recertification audit follows after three years, which reviews existing processes and responds to changes in requirements. This guarantees a permanently high level of information security.